Praisonaiagents
This hub aggregates every CVE we track for Praisonaiagents, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
48
CVEs tracked
7
Critical
15
High
0
In CISA KEV
Severity distribution
HIGH15MEDIUM8CRITICAL7
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
20
3
11
2
5
7
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Praisonaiagents.
- CVE-2026-57112PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools8.3
- CVE-2026-57129PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal7.5
- CVE-2026-57120PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder6.5
- CVE-2026-57123PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in9.8
- CVE-2026-57130PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters8.1
- CVE-2026-57115PraisonAI: SpiderTools redirect-target SSRF protection bypass6.5
- CVE-2026-57125PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass9.8
- CVE-2026-55530PraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool6.1
- CVE-2026-55526PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)8.5
- CVE-2026-55528praisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862)8.2
- CVE-2026-55525PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl7.5
- CVE-2026-55522PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code7.8
- CVE-2026-47395PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context5.5
- CVE-2026-47390PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings5.5
- GHSA-4pcv-mg8v-vrgfPraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
Product normalization is registry-driven with AI assist and human review. How it works